Misreporting Attacks in Software-Defined Networking

被引:2
|
作者
Burke, Quinn [1 ]
McDaniel, Patrick [1 ]
La Porta, Thomas [1 ]
Yu, Mingli [1 ]
He, Ting [1 ]
机构
[1] Penn State Univ, State Coll, PA 16801 USA
基金
美国国家科学基金会;
关键词
Network security; SDN; Load balancing;
D O I
10.1007/978-3-030-63086-7_16
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Load balancers enable efficient use of network resources by distributing traffic fairly across them. In software-defined networking (SDN), load balancing is most often realized by a controller application that solicits traffic load reports from network switches and enforces load balancing decisions through flow rules. This separation between the control and data planes in SDNs creates an opportunity for an adversary at a compromised switch to misreport traffic loads to influence load balancing. In this paper, we evaluate the ability of such an adversary to control the volume of traffic flowing through a compromised switch by misreporting traffic loads. We use a queuing theoretic approach to model the attack and develop algorithms for misreporting that allow an adversary to tune attack parameters toward specific adversarial goals. We validate the algorithms with a virtual network testbed, finding that through misreporting the adversary can draw nearly all of the load in the subnetwork (+750%, or 85% of the load in the system), or an adversary-desired amount of load (a target load, e.g., +200%) to within 12% error of that target. This is yet another example of how depending on untrustworthy reporting in making control decisions can lead to fundamental security failures.
引用
收藏
页码:276 / 296
页数:21
相关论文
共 50 条
  • [31] Software-Defined Networking: A Comprehensive Survey
    Kreutz, Diego
    Ramos, Fernando M. V.
    Verissimo, Paulo Esteves
    Rothenberg, Christian Esteve
    Azodolmolky, Siamak
    Uhlig, Steve
    PROCEEDINGS OF THE IEEE, 2015, 103 (01) : 14 - 76
  • [32] Software Defined Networking: Attacks and Countermeasures
    Abd Elazim, Nada Mostafa
    Sobh, Mohamed A.
    Bahaa-Eldin, Ayman M.
    PROCEEDINGS OF 2018 13TH INTERNATIONAL CONFERENCE ON COMPUTER ENGINEERING AND SYSTEMS (ICCES), 2018, : 555 - 567
  • [33] Modelling Software-Defined Networking: Software and hardware switches
    Singh, Deepak
    Ng, Bryan
    Lai, Yuan-Cheng
    Lin, Ying-Dar
    Seah, Winston K. G.
    JOURNAL OF NETWORK AND COMPUTER APPLICATIONS, 2018, 122 : 24 - 36
  • [34] A novel programmable software datapath for Software-Defined Networking
    Osinski, Tomasz
    Pahmaka, Jan
    Kossakowski, Mateusz
    Tran, Frederic Dang
    Bonfoh, El-Fadel
    Tarasiuk, Halina
    PROCEEDINGS OF THE 18TH INTERNATIONAL CONFERENCE ON EMERGING NETWORKING EXPERIMENTS AND TECHNOLOGIES, CONEXT 2022, 2022, : 245 - 260
  • [35] Design optimization-based software-defined networking scheme for detecting and preventing attacks
    Charanarur, Panem
    Hung, Bui Thanh
    Chakrabarti, Prasun
    Shankar, S. Siva
    MULTIMEDIA TOOLS AND APPLICATIONS, 2024, 83 (28) : 71151 - 71169
  • [36] Early Detection of Abnormal Attacks in Software-Defined Networking Using Machine Learning Approaches
    Chuang, Hsiu-Min
    Liu, Fanpyn
    Tsai, Chung-Hsien
    SYMMETRY-BASEL, 2022, 14 (06):
  • [37] Machine learning assisted snort and zeek in detecting DDoS attacks in software-defined networking
    AbdulRaheem M.
    Oladipo I.D.
    Imoize A.L.
    Awotunde J.B.
    Lee C.-C.
    Balogun G.B.
    Adeoti J.O.
    International Journal of Information Technology, 2024, 16 (3) : 1627 - 1643
  • [38] Attacks against Network Functions Virtualization and Software-Defined Networking: State-of-the-art
    Reynaud, Francois
    Aguessy, Francois-Xavier
    Bettan, Olivier
    Bouet, Mathieu
    Conan, Vania
    2016 IEEE NETSOFT CONFERENCE AND WORKSHOPS (NETSOFT), 2016, : 471 - 476
  • [39] A Novel Hybrid Flow-based Handler with DDoS Attacks in Software-Defined Networking
    Phan, Trung V.
    Nguyen Khac Bao
    Park, Minho
    2016 INT IEEE CONFERENCES ON UBIQUITOUS INTELLIGENCE & COMPUTING, ADVANCED & TRUSTED COMPUTING, SCALABLE COMPUTING AND COMMUNICATIONS, CLOUD AND BIG DATA COMPUTING, INTERNET OF PEOPLE, AND SMART WORLD CONGRESS (UIC/ATC/SCALCOM/CBDCOM/IOP/SMARTWORLD), 2016, : 350 - 357
  • [40] OpenSIP: Toward Software-Defined SIP Networking
    Montazerolghaem, Ahmadreza
    Moghaddam, Mohammad Hossein Yaghmaee
    Leon-Garcia, Alberto
    IEEE TRANSACTIONS ON NETWORK AND SERVICE MANAGEMENT, 2018, 15 (01): : 184 - 199